logo

Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution

ID: ede569a8-5c8d-5127-8bd6-01152f9065a7

STIX ID: report--ede569a8-5c8d-5127-8bd6-01152f9065a7

Feed Name: Palo Alto Networks Unit 42

Threat Score
88/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Justin Moore and Unit 42

...
...

Unit 42 reports a critical buffer-overflow vulnerability (CVE-2026-0300) in the PAN-OS User-ID Authentication Portal that allows unauthenticated root code execution; a likely state-sponsored cluster (CL-STA-1132) has exploited this flaw to inject shellcode, deploy tunneling tools (EarthWorm, ReverseSocks5), perform Active Directory enumeration using firewall credentials, and erase logs to cover tracks. The advisory includes IOCs (IP addresses, hashes, download URLs, user-agent strings, and file paths), recommended mitigations (restrict or disable the portal, enable Threat ID protections), and product-specific defenses for Palo Alto customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.